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(57) Abstract 

The invention relates to a procedure for carrying out checking functions 
relating to safety management in a mobile communication network and/or in a 
wireless local network during call setup. In the procedure, information about 
the degree of occupancy of a data processing apparatus implementing the 
checking functions in a network element, such as a mobile communication 
switching centre and/or the access node of a wireless local network, is 
continuously determined, the frequency of execution of the checking functions 
is adjusted based on the occupancy information thus determined, and checking 
functions are carried out on the calls according to the checking frequency 
defined for the respective degree of occupancy. 




imme liatc_assig 



13 



cess parte 



access pdrt on O 
[l ^chaimb_re<niired 



ES 



J channel 



Satan (on 



DDCHestabi 



jerv_req) 
establish 



TCfl signaling part 

Register functions 



idermfictti m_request 




assignme itjcommand 
part 
cation 



started at AN 



10 



j l | identificg 1 ioii respor se^ , 

'decision about carrying 
out identification 
(messages 12 and 13) 
a xthentificat on roquBI 



autbentifi cation_resj onso 



encrypfon signal Ac. 



Decision about carrying 
out equipment identity 
check 



BNSOOCtD: <WO 9B33U7A1 I > 



I 

V 



FOR THE PURPOSES OF INFORMATION ONLY 
Codes used to identify States party to the PCX on the front pages of pamphlets pushing intemationa. applications under the PCX. 



AL 


Albania 


AM 


Armenia 


AT 


Austria 


AU 


Australia 


AZ 


Azerbaijan 


BA 


Bosnia and Herzegovina 


BB 


Barbados 


BE 


Belgium 


BF 


Burkina Faso 


BG 


Bulgaria 


BJ 


Benin 


BR 


Brazil 


BV 


Belarus 


CA 


Canada 


CF 


Central African Republic 


CG 


Congo 


CH 


Switzerland 


CI 


Cote d'lvoire 


CM 


Cameroon 


CN 


China 


CU 


Cuba 


CZ 


Czech Republic 


DE 


Germany 


DK 


Denmark 


EE 


Estonia 



FI 

FR 

GA 

GB 

GE 

GH 

GN 

GR 

HU 

IE 

It 

IS 

IT 

JP 

KE 

KG 

KP 

KR 

KZ 

LC 

LI 

LK 

LR 



Spain 
Finland 
France 
Gabon 

United Kingdom 

Georgia 

Ghana 

Guinea 

Greece 

Hungary 

Ireland 

Israel 

Iceland 

Italy 

Japan 

Kenya 

Kyrgyzstan 

Democratic People's 

Republic of Korea 

Republic of Korea 

Kazakstan 

Saint Lucia 

Liechtenstein 

Sri Lanka 

Liberia 



LS 

LT 

LU 

LV 

MC 

MD 

MG 

MK 

ML 
MN 
MR 
MW 
MX 
NE 
NL 
NO 
NZ 
PL 
FT 
RO 
RU 
SD 
SE 
SG 



Lesotho 

Lithuania 

Luxembourg 

Latvia 

Monaco 

Republic of Moldova 

Madagascar 

The former Yugoslav 

Republic of Macedonia 

Mali 

Mongolia 

Mauritania 

Malawi 

Mexico 

Niger 

Netherlands 

Norway 

New Zealand 

Poland 

Portugal 

Romania 

Russian Federation 

Sudan 

Sweden 

Singapore 



SI 


Slovenia 


SK 


Slovakia 


SN 


Senegal 


sz 


Swaziland 


TD 


Chad 


TG 


Togo 


TJ 


Tajikistan 


TM 


Turkmenistan 


TR 


Turkey 


TT 


Trinidad and Tobago 


UA 


Ukraine 


UG 


Uganda 


US 


United States of America 


uz 


Uzbekistan 


VN 


Viet Nam 


YU 


Yugoslavia 


zw 


Zimbabwe 



BMSDOCID: <WO_9833347A1J_> 



WO 98/33347 PCT/FI98/00030 



PROCEDURE FOR CARRYING OUT CHECKING FUNCTIONS RELATING 
TO SAFETY MANAGEMENT IN A MOBILE COMMUNICATION NETWORK 
AND/OR IN A WIRELESS LOCAL NETWORK 

The present invention relates to a procedure 
5 for carrying out checking functions related to safety 
management during call setup in a mobile communication 
network or in a wireless local network. 

During call setup in a mobile communication 
network and/or in a wireless local network, various 

10 checking functions relating to network safety manage- 
ment are carried out. These checking functions are de- 
signed to prevent unauthorised network access for 
users not entitled to use the network, and to prevent 
the use of e.g. a mobile station that has been repor- 

15 ted lost. Such checking functions are performed during 
call setup normally by means of a data processing ap- 
paratus used for operation control, located in a mobi- 
le communication switching centre and/or in the access 
node of a wireless local network. The problem is that 

20 such checking functions take up call setup time. The 
heavier the load on the data processing apparatus, the 
more the call setup is retarded. Slow call setup again 
is unpleasant for the user. Especially in the case of 
a wireless local network (WLL) , fast setup of outgoing 

25 calls is important. 

The object of the present invention is to 
eliminate the drawbacks described above. 

A specific object of the invention is to pre- 
sent a procedure that enables the call setup speed to 

30 be kept within reasonable limits in conditions of a 
high level of occupancy, yet without substantially im- 
pairing network safety. 

The procedure of the invention is characte- 
rised by the features presented in claim 1. 

3 5 In the procedure of the invention, informati- 

on about the occupancy of a data processing apparatus 
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implementing checking functions in a network element, 
such as a mobile communication switching centre and/or 
the access node of a wireless local network, is conti- 
nuously determined, the frequency of execution of the 
checking functions is adjusted based on the occupancy 
information thus determined, and checking functions 
are carried out on calls according to the checking 
frequency defined for the respective degree of occu- 
pancy . 

The invention has the advantage that the pro- 
cedure allows a workable and self-adjusting compromise 
between call setup speed and safety. In spite of a 
high degree of occupancy of the data processing appa- 
ratus performing checking functions, the call setup 
time will not substantially exceed the normal setup 
time because some calls are passed through without a 
safety check. However, safety is not substantially im- 
paired as it is very unlikely for the next calls from 
the same user's mobile station to be passed through 
unchecked, because the degree of occupancy determining 
the checking frequency varies continuously. 

In an embodiment of the invention, when the 
degree of occupancy is lower than a predetermined li- 
mit, the checking functions are carried out at a spe- 
cified high checking frequency. In conditions of low 
occupancy, every call, or 100% of the calls, could be 
checked . 

In an embodiment of the procedure, when the 
degree of occupancy is higher than a predetermined li- 
mit, the checking functions are carried out at a spe- 
cified low checking frequency. In conditions of high 
occupancy, a definition can be made to the effect that 
e.g. only 5% of the calls are checked. 

in an embodiment of the procedure, the limits 
35 are parameters that can be changed by the network ope- 
rator . 
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In an embodiment of the procedure, the 
checking function for which the checking frequency is 
adjusted is authentication or the checking of the 
right of access, wherein the subscriber data for the 
5 mobile station are verified during call setup and pos- 
sible illicit network access is denied. 

In an embodiment of the procedure, the 
checking function for which the checking frequency is 
adjusted is an equipment identity check, wherein the 

10 equipment identity code sent by the mobile station is 
checked during call setup by comparing it with a re- 
gister of equipment identity codes for mobile stations 
reported stolen and/or defective. 

In an embodiment of the procedure, the equip- 

15 ment identity check is verification of the IMEI code. 
IMEI is an international mobile station equipment 
identity code, which enables the mobile station to be 
unambiguously identified. E.g.. in the GSM system, the 
IMEI code is a 15 -digit number and it is divided into 

20 a 6-digit type approval code (TAC) , a 2-digit assembly 
code (FAC) identifying the assembling factory, a 6- 
digit serial number and a 1 -digit reserve number. 

In an embodiment of the procedure, the mobile 
communication network is a GSM/DCS mobile communicati - 

25 on network. GSM is a European digital mobile communi- 
cation system (GSM, Global System for Mobile Communi- 
cations) . DCS (Digital Cellular System) is a mobile 
communication system standardized by the ETSI and 
based on the GSM specification, aimed at a more effec- 

30 tive use of microcells; e.g. DCS-1800 works in a fre- 
quency range of 1800 MHz. 

In an embodiment of the procedure, the wire- 
less local network is a so-called WLL (Wireless Local 
Loop) network. In a WLL network, the subscriber's sta- 

35 tion is connected via a radio link to an access node 
or WLL controller. The WLL system may be based e.g. on 
technology used in a mobile communication system, such 
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as the GSM/DCS- 1800 technology. Between the sub- 
scriber's station and the access node there is a base 
transceiver station, through which call signals sent 
by the terminal device over a radio channel are trans - 
5 mi t ted via the access node to a public telephone net- 
work and vice versa. The access node or WLL controller 
can be connected to the telephone exchange using e.g. 
the V5.1 or V5.2 protocol consistent with the ETSI 
standards . 

10 m an embodiment of the procedure, identity 

data left unchecked because of high occupancy are sto- 
red for possible later checking. 

In the following, the invention will be de- 
scribed in detail by the aid of an embodiment example 

15 by referring to the attached drawing, which presents a 
call setup signalling diagram according to an embodi- 
ment of the procedure of the invention in a case where 
a subscriber's station in a wireless local network 

originates a call. 
20 The signalling diagram in the figure repre- 

sents a call originated by a subscriber's station in a 
wireless local network WLL, substantially correspond- 
ing to a mobile originated call MOC consistent with 
the GSM specifications. The system components in the 
25 diagram are a base transceiver station BTS, an access 
node AN and a local exchange LE. 

The access node AN contains three program 
blocks called registers. These are an equipment regis- 
ter, an authentication register and, placed hierarchi- 
30 cally above these, a main register. The equipment reg- 
ister contains the equipment numbers (IMEI) . The 
* equipment number may be placed on a white, grey or 
black list, and in an equipment identity check the 
equipment register returns the IMEI list colour. The 
35 authentication register produces the triplets needed 
for identification and contains the information re- 
quired for identification. The functions of the main 
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register include deciding about the execution of 
checking functions. 

In the GSM/DCS world, the following register 
terms are used: authentication register AUC; AC 
5 (authentication centre) , equipment register EIR 
(equipment identity register) and main register VLR 
(visitor location register) . In wireless local loop 
environment, the main register block is termed WFR 
(wireless fixed register) . 

10 The call setup procedure in a wireless local 

network in a so-called non- transparent mode as pre- 
sented in the figure is substantially similar to call 
setup in a normal GSM system. In a wireless local net- 
work system, the access node AN also comprises func- 

15 tions that are included in the mobile services switch- 
ing centre/visitor location register MSC/VLR and home 
location register/authentication centre/equipment 
identity register of a normal GSM system. The sub- 
scriber's stations in a wireless local loop WLL commu- 

20 nicate with the access node AN over a radio link. The 
signalling between the. subscriber's station WLL' and 
the access node AN consists of message-based signal- 
ling consistent with the GSM specifications (GSM/DCS) . 
The access node AN again is connected to a wired net- 

25 work local exchange LE via an V5.2 interface consis- 
tent with the ETS 300 347-1 standard. 

When a subscriber lifts the receiver, the 
subscriber's station generates a local dialling tone. 
The subscriber has a predetermined length of time to 

30 dial the first digit. The dialling tone goes off as 
soon as the first digit has been dialled. Call setup 
is started upon the lapse of a predetermined period of 
time after the last digit has been dialled. The sub- 
scriber's station WLL requests a call by sending a 
35 CHANNEL REQUEST message to the base transceiver sta- 
tion BTS. The base transceiver station BTS transmits 
the channel request to the access node AN, which 
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starts searching for a communication channel. After a 
communication channel has been successfully reserved, 
the access node activates the channel by sending a 
CHANNEL ACTIVATION message to the base transceiver 
station BTS. The base transceiver station BTS acknowl- 
edges successful activation by returning a CHANNEL 
ACTIVATION ACK message. The base transceiver station 
BTS starts transmission and reception over this chan- 
nel using the capacity and timing data received in the 
CHANNEL ACTIVATION message. After successful activa- 
tion of the communication channel, the access node AN 
transmits an IMMEDIATE ASSIGNMENT COMMAND message to 
the base transceiver station BTS. This message con- 
tains an IMMEDIATE ASSIGNMENT message, which is sent 
15 by the base transceiver station BTS to the sub- 
scriber's station WLL. Upon receiving the IMMEDIATE 
ASSIGNMENT message, the subscriber's station WLL is 
tuned to the communication channel assigned and starts 
setting up a signalling link over the network. The 
20 subscriber's station WLL transmits a layer-2 SABM mes- 
sage to the base transceiver station BTS via the com- 
munication channel. SABM contains a layer-3 service 
request message. The base transceiver station trans- 
mits the service request of the subscriber's station 
2 5 further to the access node^ AN in an ESTABLISH 
INDICATION message, which includes a temporary mobile 
subscriber identity code TMSI . The base transceiver 
station BTS acknowledges the SABM message by sending a 
UA frame to the subscriber's station WLL. At this 
stage, the wireless fixed register program block WFR 
issues to the control program an inquiry about the oc- 
cupancy of the computer unit and, based on this, de- 
cides whether authentication is to be carried out and 
somewhat later, after possible authentication, en- 
crypting message etc., the wireless fixed register 
likewise decides whether an equipment identity check 
(IMEI check) is to be carried out or not. The rest of 
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the message exchange in the call setup procedure is 
done in accordance with the conventional scheme, which 
will not be described here in detail. 

The checking functions can be implemented for 
5 example in ' such a way that if the degree of occupancy 
of the computer unit performing the checking functions 
is 30% or below, then the authentication and equipment 
identity checks are carried out for every call. If the 
computer unit's occupancy is 70% or above, no checking 

10 functions are performed at all. When the occupancy is 
between 30 - 70 %, the checking frequency could grow 
e.g. linearly from a frequency covering all calls to a 
frequency covering every twentieth call. The limits 
are preferably parameters subject to change by the op- 

15 erator. In addition, it is possible to use an arrange- 
ment in which the checking frequency and the equipment 
authentication frequency are somewhat different from 
each other so that these functions will not have to be 
performed on the same call when not all calls are 

20 checked. 

The invention is not limited to the embodi- 
ment example presented above, but many variations are 
possible within the framework of the inventive idea 
defined by the claims. 
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CLAIMS 

1. Procedure for carrying out checking 
functions relating to safety management in a mobile 
communication network and/or in a wireless local net- 
5 work during call setup, characterized in 
that 

information about the degree of occupancy of 
a data processing apparatus implementing the checking 
functions in a network element, such as a mobile com- 

10 munication switching centre and/or the access node of 
a wireless local network, is continuously determined, 

the frequency of execution of the checking 
functions is adjusted based on the occupancy informa- 
tion thus determined, and 

15 checking functions are carried out on the 

calls according to the checking frequency defined for 
the respective degree of occupancy. 

2. Procedure as defined in claim 1, cha- 
racterized in that, when the occupancy is below 

20 a predetermined limit, the checking functions are car- 
ried out at a predetermined high checking frequency. 

3. Procedure as defined in claim 1 or 2, 
characterized in that, when the occupancy is 
above a predetermined limit, the checking functions 

25 are carried out at a predetermined low checking fre- 
quency . 

4. Procedure as defined in claim 2 or 3, 
characterized in that the limits are parame- 
ters that can be changed by the network operator. 

30 5. Procedure as defined in any one of claims 

1 - 4, characterized in that the checking 
function for which the checking frequency is adjusted 
is authentication, or the checking of the right of ac- 
cess, wherein the subscriber data for the mobile sta- 

35 t ion are verified during call setup and possible illi- 
cit network access is denied. 
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6. Procedure as defined in any one of claims 
1 - 5, characterized in that the checking 
function for which the checking frequency is adjusted 
is an equipment identity check, wherein the equipment. 

5 identity code sent by the mobile station is checked 
during call setup by comparing it with a register of 
equipment identity codes for mobile stations reported 
stolen and/or defective. 

7. Procedure as defined in claim 7, c h a - 
10 racterized in that the equipment identity check 

is verification of the IMEI code. 

8. Procedure as defined in any one of claims 
1 - 7, characterized in that the wireless 
local network is a so-called WLL network (Wireless Lo- 

15 cal Loop) . 

10. Procedure as defined in any one of claims 
1 - 9, characterized in that identity data 
left unchecked because of a high degree of occupancy 
are stored for possible later checking. 
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